London, UK
2015
  |  By Brendan Hann
AI coding agents produce authorization logic that compiles, passes review, and enforces the wrong policy. Broken access control ranks first in the OWASP Top 10:2025, where 100% of applications tested showed some form of it, across 1,839,701 recorded occurrences, the highest count of any category on the list. One part of that category is also the part that pattern-based scanning was never built to reach.
  |  By Brendan Hann
Agentic AppSec (agentic application security) is the practice of using a team of AI security agents to run an organization's entire application security program: understanding the application, modeling its threats, finding the vulnerabilities that matter, deciding what is worth fixing, generating and validating fixes, and proving those fixes hold. It applies continuously to both new code and the existing backlog.
  |  By Daniel Berman
Today, we're announcing that Govern Agent Behavior, the capability within Evo Agentic Development Security (ADS) that controls what AI coding agents are allowed to do at runtime, is generally available, starting with MCP Governance.
  |  By Brendan Hann
Every security program has one: a queue of a few thousand findings, or a few hundred thousand, that nobody has worked through and nobody expects to. Most teams file it under technical debt, a cost carried on purpose, paid down when there is room, and tolerable because the interest rate stays low. That accounting held for a long time, because it rested on a single assumption: almost nothing in the queue would ever be reached, or exploited, by anyone.
  |  By Nina Kanti
Evo already knows which AI Assets your teams pulled into your repos, which MCP servers and skills are sitting on your developer machines, which of them carry risk, and which policies they break. Getting to any of it created friction: you leave the tool you are working in, filter a UI, export a CSV, and rebuild the chart you built last quarter, every time it’s needed.
  |  By Manoj Nair
For the past year, I've described this as an AI fog: competing claims, uncertain risks, and leaders struggling to see what mattered. The winds are up now. AI is accelerating software creation, exposing years of accumulated vulnerabilities, and handing both attackers and defenders capabilities that operate at machine speed.
  |  By Ezra Tanzer
Stopping new security issues in agent-generated code from being deployed is, architecturally, a solved problem. Prevention is the act of keeping a new vulnerability in code from reaching production at any point in the development and release process, including but not limited to preventing its introduction in a feature branch.
  |  By Damian Tommasino
Imagine getting three separate security reports back for your new enterprise AI assistant: On paper, the application looks ready for production, but in reality, a threat actor bypasses your guardrails in minutes. How? By using the AI model as an intermediary. The attacker steers the LLM to invoke the internal utility tool, thereby bridging an untrusted prompt directly to the backend execution sink.
  |  By Snyk Team
Six new security issues for every one issue remediated. That's the ratio Snyk research has found, and it's why the AI Security Engineers Community gave an hour of livestream time to fixing rather than finding. Play Video: Remediation Agents Demystified: Your AI Teammate for Fixing Security Bugs Remediation Agents Demystified paired a fireside chat with a live demo.
  |  By Stephen Thoemmes
We benchmarked how well leading models produce vulnerability fixes that are both secure and functional, across ~150 real vulnerable code samples in JavaScript, Java, and Python. We ran each model on its own and with Snyk Intelligence (the new agentic Agent Fix architecture). The headline findings.
  |  By Snyk
-OpenAI has completely overhauled its model naming system with the release of GPT-5.6, introducing three distinct tiers: Sol, Terra, and Luna. In this video, we put OpenAI's new flagship model, GPT-5.6 Sol, to the ultimate test. Using the Codex extension in VS Code, we throw our classic "Build me a secure notes app or I get fired" prompt at Sol. Watch as we break down the pricing and reasoning differences of the new tiers, run a full security audit using Snyk, and see if Sol's $5/$30 price tag is truly production-ready or if a small local CSRF bug gets us "fired" first.
  |  By Snyk
In this video, we break down why skipping code reviews is a massive mistake that will ultimately slow you down, leave you vulnerable, and compromise your system's accountability. We dive into three concrete reasons why reviewing AI-generated pull requests actually makes you a faster, safer developer, including a real-world story of a production bug caught in under 90 seconds. Resources Chapters.
  |  By Snyk
GLM 5.2 just launched from Z.ai, and it might be one of the biggest threats yet to the frontier model premium. It’s open, significantly cheaper than Claude Opus 4.8, and claims to deliver near-frontier coding performance across major benchmarks. But benchmarks only matter if the model can actually build something production-ready.
  |  By Snyk
In this video, we break down how to properly set up and use AI extension points - specifically MCP (Model Context Protocol) servers, Rules, Skills, and Hooks - to supercharge your development workflow. Using practical, security-flavored examples with Claude Code and Snyk, you'll learn how to configure a local project environment that automatically catches vulnerabilities before they ever hit your codebase. Whether you use the Claude CLI, VS Code extensions, or alternate AI ecosystems like Cursor or Gemini, you can use these exact steps as a blueprint to automate any workflow in your project.
  |  By Snyk
Over 78% of developers are using Claude for coding, but almost everyone is leaving its single most powerful feature switched off: Claude Skills. In this video, we break down what Claude Skills are, how they use "progressive disclosure" to keep your context window light, and the 7 best engineering skills you can install this week to completely supercharge your workflow.
  |  By Snyk
We put Anthropic’s new Claude Opus 4.8 to the test using our standard benchmark: building a secure, production-ready Notes app. Anthropic claims this model is four times less likely to let security flaws slip through. Operating on "Ultra Code" mode, the AI navigates environment blocks, writes its own E2E security test suite, and runs dependency audits. We walkthrough the final app and run a security scan using the Snyk CLI to see if Claude's code is truly safe to deploy.
  |  By Snyk
235,000 installs per week. That’s how quickly developers are downloading AI agent skills — packages that give AI coding agents new capabilities like shell access, file system operations, cloud access, and deployment permissions. But unlike traditional npm packages, agent skills introduce a completely new security problem: natural language instructions that AI agents can interpret and execute autonomously.
  |  By Snyk
On May 11, 2026, the TanStack namespace was hit by a "Mini Shai-Hulud" supply chain attack. Unlike typical attacks, this did not involve stolen credentials; instead, the threat group TeamPCP hijacked the legitimate GitHub Actions release pipeline. This video covers the technical details of the OIDC token extraction, the "Dead Man's Switch" that triggers a rm -rf / upon credential revocation, and the mandatory remediation order you must follow to save your data. We also discuss how to harden your workflow using release-age cooldowns and OIDC pinning.
  |  By Snyk
Are you confused by the terminology surrounding AI coding tools? You aren't alone. In this video, we break down the four essential components that transform a basic LLM into a powerful coding agent: Rules, Skills, Hooks, and the Model Context Protocol (MCP).
  |  By Snyk
GPT-5.5 vs Claude Opus 4.7 - two flagship AI models dropped one week apart, and both claim to be the best at agentic coding. We put that to the test by giving each model the exact same prompt: build a production-ready, secure note-taking application from scratch. But we didn't stop at reviewing the code. We actually tried to break it by running real security tests against each app to see whether AI-generated code can be trusted with user data. The results were not what we expected.
  |  By Snyk
Forrester conducted a customer study to get insights into why organizations choose Snyk to help them tackle and implement developer-first security. Read the report to dive into the benefits, cost and value ROI for Snyk.
  |  By Snyk
This book will help both development and application security architects and practitioners address the risk of vulnerable open source libraries and discuss why such vulnerable dependencies are the most likely to be exploited by attackers.
  |  By Snyk
This book reviews how the serverless paradigm affects the security of an application, and dives into the benefits it brings.
  |  By Snyk
Snyk's annual State of Open Source Security Report 2020 is here. Download it now to learn how Open Source security is evolving.
  |  By Snyk
81% of security and development professionals believe developers are responsible for open source security - but many organizations are still unsure how to start building a culture and practice of DevSecOps. Puppet & Snyk's study is digging deeper into the trends of DevSecOps adoption.
  |  By Snyk
"Shift left" has become the holy grail for security teams today but organizations are still struggling to successfully implement some of the key processes that shifting security left entails. A new study sponsored by Snyk and conducted by Enterprise Strategy Group (ESG) has found that while developers are indeed being given more responsibility for testing their applications for security issues, they simply don't have the knowledge or right set of tools to do so.
  |  By Snyk
The 2020 Gartner Market Guide for SCA is here! Recent Gartner survey finds that over 90% of organizations leverage OSS in application development - and as a result, security of open source packages was the highest ranked concern for respondents. These concerns have led to a growing market, addressed by various vendors for SCA tools that mitigate the risk of OSS. New trends emerge with devops on the rise - as the market shifts towards developer-friendly SCA tools.

Snyk is an open source security platform designed to help software-driven businesses enhance developer security. Snyk's dependency scanner makes it the only solution that seamlessly and proactively finds, prioritizes and fixes vulnerabilities and license violations in open source dependencies and container images.

Security Across the Cloud Native Application Stack:

  • Open Source Security: Automatically find, prioritize and fix vulnerabilities in your open source dependencies throughout your development process.
  • Code Security: Find and fix vulnerabilities in your application code in real-time during the development process.
  • Container Security Find and automatically fix vulnerabilities in your containers at every point in the container lifecycle.
  • Infrastructure as Code Security Find and fix Kubernetes and Terraform infrastructure as code issues while in development.

Develop Fast. Stay Secure.